Impact
The vulnerability in Oracle Hyperion Financial Management allows an unauthenticated attacker with network access via TLS to create, delete, or modify critical data, and to access all data stored in the application. This results in confidentiality and integrity impacts. The flaw is a missing authentication issue (CWE-306) that bypasses the need for credentials and permits unauthorized actions.
Affected Systems
Affected is Oracle Corporation’s Hyperion Financial Management version 11.2.26.0.000. No other product versions are listed as affected in the available data.
Risk and Exploitability
The severity is a CVSS 3.1 base score of 7.4, indicating a high severity rating. The EPSS score is below 1%, indicating a low likelihood of exploitation in the wild at this time, and the vulnerability is not catalogued in the CISA KEV list. The attack vector is network over TLS, requiring the attacker to reach the Hyperion service from outside, but no authentication or privileged access is needed because the flaw is a missing authentication issue (CWE-306). The exploitation could allow an attacker to modify or delete critical data, compromising the integrity and confidentiality of financial information.
OpenCVE Enrichment